General Info

File name

boost-speed-setup.exe

Full analysis
https://app.any.run/tasks/1d04a522-37f5-48af-8dbd-a8ad89ca1b4c
Verdict
Malicious activity
Analysis date
10/9/2019, 21:48:05
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

a1137247d5ecf1f27fd72f42d50f7fe3

SHA1

152e52a07dc63ecfb0895b7ea1817bb10de3d6b9

SHA256

bf8ecb54d97a8a6adee4872c165b3ca9933c104f0924a8ead9e8fe8a89309490

SSDEEP

393216:G5oUiKmNKEf1CnGekNggVN100+uPBl2MxNMfzQ6PgsrS/c5AnH402Dbx6CLFSNga:/xsEIToN1ms2Gefk64spS402vhA7

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
300 seconds
Additional time used
240 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 68.0.1 (x86 en-US) (68.0.1)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • Integrator.exe (PID: 2208)
  • Integrator.exe (PID: 2232)
  • regsvr32.exe (PID: 3308)
  • regsvr32.exe (PID: 3360)
  • DiskDefrag.exe (PID: 3144)
  • regsvr32.exe (PID: 2492)
  • Integrator.exe (PID: 3780)
Application was dropped or rewritten from another process
  • Integrator.exe (PID: 3120)
  • Integrator.exe (PID: 2208)
  • DiskDefrag.exe (PID: 3144)
  • Integrator.exe (PID: 2232)
  • Integrator.exe (PID: 3780)
Changes settings of System certificates
  • Integrator.exe (PID: 3780)
  • boost-speed-setup.tmp (PID: 2436)
Registers / Runs the DLL via REGSVR32.EXE
  • boost-speed-setup.tmp (PID: 2436)
Reads Windows owner or organization settings
  • Integrator.exe (PID: 2232)
  • Integrator.exe (PID: 2208)
  • DiskDefrag.exe (PID: 3144)
  • Integrator.exe (PID: 3780)
  • boost-speed-setup.tmp (PID: 2436)
Reads CPU info
  • Integrator.exe (PID: 2232)
  • Integrator.exe (PID: 3780)
Reads the Windows organization settings
  • Integrator.exe (PID: 2208)
  • Integrator.exe (PID: 2232)
  • DiskDefrag.exe (PID: 3144)
  • Integrator.exe (PID: 3780)
  • boost-speed-setup.tmp (PID: 2436)
Adds / modifies Windows certificates
  • Integrator.exe (PID: 3780)
  • boost-speed-setup.tmp (PID: 2436)
Creates COM task schedule object
  • regsvr32.exe (PID: 2492)
  • regsvr32.exe (PID: 3308)
  • regsvr32.exe (PID: 3360)
Creates files in the user directory
  • boost-speed-setup.tmp (PID: 2436)
Reads the machine GUID from the registry
  • boost-speed-setup.tmp (PID: 2436)
Reads the cookies of Google Chrome
  • boost-speed-setup.tmp (PID: 2436)
Executable content was dropped or overwritten
  • boost-speed-setup.exe (PID: 3824)
  • boost-speed-setup.exe (PID: 2532)
  • boost-speed-setup.tmp (PID: 2436)
Reads Windows Product ID
  • boost-speed-setup.tmp (PID: 2436)
Reads the cookies of Mozilla Firefox
  • boost-speed-setup.tmp (PID: 2436)
Manual execution by user
  • Integrator.exe (PID: 2208)
  • Integrator.exe (PID: 3120)
Dropped object may contain Bitcoin addresses
  • boost-speed-setup.tmp (PID: 2436)
Creates a software uninstall entry
  • boost-speed-setup.tmp (PID: 2436)
Application was dropped or rewritten from another process
  • reader.exe (PID: 3800)
  • boost-speed-setup.tmp (PID: 3528)
  • boost-speed-setup.tmp (PID: 2436)
Loads dropped or rewritten executable
  • boost-speed-setup.tmp (PID: 2436)
Creates files in the program directory
  • boost-speed-setup.tmp (PID: 2436)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable (generic) (42.6%)
.exe
|   Win16/32 Executable Delphi generic (19.5%)
.exe
|   Generic Win/DOS Executable (18.9%)
.exe
|   DOS Executable Generic (18.9%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2016:04:06 16:39:04+02:00
PEType:
PE32
LinkerVersion:
2.25
CodeSize:
66560
InitializedDataSize:
438272
UninitializedDataSize:
null
EntryPoint:
0x117dc
OSVersion:
5
ImageVersion:
6
SubsystemVersion:
5
Subsystem:
Windows GUI
FileVersionNumber:
11.1.0.0
ProductVersionNumber:
11.1.0.0
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
Neutral
CharacterSet:
Unicode
Comments:
This installation was built with Inno Setup.
CompanyName:
Ausl˜ogics
FileDescription:
Ausl˜ogics Boos˜tSpeed Installation File
FileVersion:
11.x
LegalCopyright:
Copyright © 2008-2019 Auslo˜gics Labs Pty Ltd
ProductName:
Ausl˜ogics Boos˜tSpeed
ProductVersion:
11.1.0.0
OriginalFileName:
boost-speed-setup.exe
InternalName:
boost-speed-setup
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
06-Apr-2016 14:39:04
Detected languages
English - United States
Comments:
This installation was built with Inno Setup.
CompanyName:
Ausl˜ogics
FileDescription:
Ausl˜ogics Boos˜tSpeed Installation File
FileVersion:
11.x
LegalCopyright:
Copyright © 2008-2019 Auslo˜gics Labs Pty Ltd
ProductName:
Ausl˜ogics Boos˜tSpeed
ProductVersion:
11.1.0.0
OriginalFilename:
boost-speed-setup.exe
InternalName:
boost-speed-setup
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0050
Pages in file:
0x0002
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x000F
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x001A
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x00000100
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
8
Time date stamp:
06-Apr-2016 14:39:04
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x0000F244 0x0000F400 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.37521
.itext 0x00011000 0x00000F64 0x00001000 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 5.7322
.data 0x00012000 0x00000C88 0x00000E00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 2.29672
.bss 0x00013000 0x000056BC 0x00000000 IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.idata 0x00019000 0x00000E04 0x00001000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 4.59781
.tls 0x0001A000 0x00000008 0x00000000 IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.rdata 0x0001B000 0x00000018 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 0.204488
.rsrc 0x0001C000 0x00068F68 0x00069000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 6.46284
Resources
1

2

3

4

5

6

7

8

9

10

11

4091

4092

4093

4094

4095

4096

11111

CHARTABLE

DVCLAL

PACKAGEINFO

MAINICON

Imports
    oleaut32.dll

    advapi32.dll

    user32.dll

    kernel32.dll

    comctl32.dll

Exports

    No exports.

Screenshots

Processes

Total processes
56
Monitored processes
13
Malicious processes
8
Suspicious processes
0

Behavior graph

+
drop and start start drop and start drop and start drop and start drop and start drop and start boost-speed-setup.exe boost-speed-setup.tmp no specs boost-speed-setup.exe boost-speed-setup.tmp reader.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs integrator.exe no specs diskdefrag.exe no specs integrator.exe no specs integrator.exe no specs integrator.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
2532
CMD
"C:\Users\admin\Desktop\boost-speed-setup.exe"
Path
C:\Users\admin\Desktop\boost-speed-setup.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Ausl˜ogics
Description
Ausl˜ogics Boos˜tSpeed Installation File
Version
11.x
Modules
Image
c:\users\admin\desktop\boost-speed-setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\version.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\shell32.dll
c:\users\admin\appdata\local\temp\is-b17a7.tmp\boost-speed-setup.tmp

PID
3528
CMD
"C:\Users\admin\AppData\Local\Temp\is-B17A7.tmp\boost-speed-setup.tmp" /SL5="$90144,25923408,505856,C:\Users\admin\Desktop\boost-speed-setup.exe"
Path
C:\Users\admin\AppData\Local\Temp\is-B17A7.tmp\boost-speed-setup.tmp
Indicators
No indicators
Parent process
boost-speed-setup.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-b17a7.tmp\boost-speed-setup.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll

PID
3824
CMD
"C:\Users\admin\Desktop\boost-speed-setup.exe" /SPAWNWND=$40126 /NOTIFYWND=$90144
Path
C:\Users\admin\Desktop\boost-speed-setup.exe
Indicators
Parent process
boost-speed-setup.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Ausl˜ogics
Description
Ausl˜ogics Boos˜tSpeed Installation File
Version
11.x
Modules
Image
c:\users\admin\desktop\boost-speed-setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\version.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\shell32.dll
c:\users\admin\appdata\local\temp\is-v355o.tmp\boost-speed-setup.tmp

PID
2436
CMD
"C:\Users\admin\AppData\Local\Temp\is-V355O.tmp\boost-speed-setup.tmp" /SL5="$D0142,25923408,505856,C:\Users\admin\Desktop\boost-speed-setup.exe" /SPAWNWND=$40126 /NOTIFYWND=$90144
Path
C:\Users\admin\AppData\Local\Temp\is-V355O.tmp\boost-speed-setup.tmp
Indicators
Parent process
boost-speed-setup.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-v355o.tmp\boost-speed-setup.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\sspicli.dll
c:\users\admin\appdata\local\temp\is-gtqsg.tmp\reader.exe
c:\users\admin\appdata\local\temp\is-gtqsg.tmp\setupcustom.dll
c:\users\admin\appdata\local\temp\is-gtqsg.tmp\vclimg250.bpl
c:\windows\system32\winmm.dll
c:\users\admin\appdata\local\temp\is-gtqsg.tmp\rtl250.bpl
c:\windows\system32\opengl32.dll
c:\windows\system32\glu32.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\wsock32.dll
c:\users\admin\appdata\local\temp\is-gtqsg.tmp\vcl250.bpl
c:\windows\system32\winspool.drv
c:\windows\system32\oledlg.dll
c:\users\admin\appdata\local\temp\is-gtqsg.tmp\axcomponentsvcl.bpl
c:\users\admin\appdata\local\temp\is-gtqsg.tmp\axcomponentsrtl.bpl
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\users\admin\appdata\local\temp\is-gtqsg.tmp\integrator.exe
c:\users\admin\appdata\local\temp\is-gtqsg.tmp\localizer.dll
c:\users\admin\appdata\local\temp\is-gtqsg.tmp\commonforms.site.dll
c:\users\admin\appdata\local\temp\is-gtqsg.tmp\cfahelper.dll
c:\windows\system32\wbem\wbemdisp.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbem\wmiutils.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\users\admin\appdata\local\temp\is-gtqsg.tmp\googleanalyticshelper.dll
c:\users\admin\appdata\local\temp\is-gtqsg.tmp\browserhelper.dll
c:\windows\system32\vaultcli.dll
c:\windows\system32\imageres.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\msftedit.dll
c:\program files\mozilla firefox\firefox.exe
c:\program files\google\chrome\application\chrome.exe
c:\program files\opera\opera.exe
c:\windows\system32\normaliz.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\credssp.dll
c:\windows\system32\secur32.dll
c:\windows\system32\gpapi.dll
c:\users\admin\appdata\local\temp\is-gtqsg.tmp\sqlite3.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\auslogics\boostspeed\integrator.exe
c:\program files\auslogics\boostspeed\unins000.exe
c:\windows\system32\regsvr32.exe
c:\windows\system32\wpdshext.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\program files\auslogics\boostspeed\diskdefrag.exe

PID
3800
CMD
"C:\Users\admin\AppData\Local\Temp\is-GTQSG.tmp\reader.exe" "C:\Users\admin\Desktop\boost-speed-setup.exe" "(x32)HKEY_LOCAL_MACHINE\\Software\\Auslogics\\BoostSpeed\\11.x\\Settings"
Path
C:\Users\admin\AppData\Local\Temp\is-GTQSG.tmp\reader.exe
Indicators
No indicators
Parent process
boost-speed-setup.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\is-gtqsg.tmp\reader.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
3360
CMD
"C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\Auslogics\BoostSpeed\DiskDoctorChecker.x32.dll"
Path
C:\Windows\system32\regsvr32.exe
Indicators
No indicators
Parent process
boost-speed-setup.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft(C) Register Server
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\program files\auslogics\boostspeed\diskdoctorchecker.x32.dll
c:\program files\auslogics\boostspeed\rtl250.bpl
c:\windows\system32\oleacc.dll
c:\windows\system32\opengl32.dll
c:\windows\system32\glu32.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\sxs.dll

PID
2492
CMD
"C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\Auslogics\BoostSpeed\TaskManagerHelper.Agent.x32.dll"
Path
C:\Windows\system32\regsvr32.exe
Indicators
No indicators
Parent process
boost-speed-setup.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft(C) Register Server
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\program files\auslogics\boostspeed\taskmanagerhelper.agent.x32.dll
c:\program files\auslogics\boostspeed\rtl250.bpl
c:\windows\system32\oleacc.dll
c:\windows\system32\opengl32.dll
c:\windows\system32\glu32.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\psapi.dll
c:\windows\system32\sxs.dll

PID
3308
CMD
"C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\Auslogics\BoostSpeed\BrowserPluginsHelper.Agent.x32.dll"
Path
C:\Windows\system32\regsvr32.exe
Indicators
No indicators
Parent process
boost-speed-setup.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft(C) Register Server
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\program files\auslogics\boostspeed\browserpluginshelper.agent.x32.dll
c:\program files\auslogics\boostspeed\rtl250.bpl
c:\windows\system32\oleacc.dll
c:\windows\system32\opengl32.dll
c:\windows\system32\glu32.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\sxs.dll

PID
3780
CMD
"C:\Program Files\Auslogics\BoostSpeed\Integrator.exe" /install /setscheduledefault /setautostart
Path
C:\Program Files\Auslogics\BoostSpeed\Integrator.exe
Indicators
No indicators
Parent process
boost-speed-setup.tmp
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
Ausl˜ogics
Description
Boo˜stSpeed
Version
11.1.0.0
Modules
Image
c:\program files\auslogics\boostspeed\integrator.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\program files\auslogics\boostspeed\axcomponentsvcl.bpl
c:\program files\auslogics\boostspeed\axcomponentsrtl.bpl
c:\windows\system32\wininet.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\version.dll
c:\program files\auslogics\boostspeed\rtl250.bpl
c:\windows\system32\mpr.dll
c:\windows\system32\opengl32.dll
c:\windows\system32\glu32.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\webio.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\program files\auslogics\boostspeed\vclimg250.bpl
c:\program files\auslogics\boostspeed\vcl250.bpl
c:\windows\system32\winspool.drv
c:\windows\system32\comdlg32.dll
c:\windows\system32\oledlg.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\faultrep.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\winsta.dll
c:\windows\system32\uxtheme.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msimg32.dll
c:\program files\auslogics\boostspeed\internetoptimizer.exe
c:\program files\auslogics\boostspeed\tweakmanager.exe
c:\program files\auslogics\boostspeed\taskmanager.exe
c:\program files\auslogics\boostspeed\duplicatefilefinder.exe
c:\program files\auslogics\boostspeed\uninstallmanager.exe
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\psapi.dll
c:\program files\auslogics\boostspeed\startupmanager.exe
c:\program files\auslogics\boostspeed\registrycleaner.exe
c:\program files\auslogics\boostspeed\diskexplorer.exe
c:\program files\auslogics\boostspeed\windowsslimmer.exe
c:\program files\auslogics\boostspeed\deepdiskcleaner.exe
c:\program files\auslogics\boostspeed\tabmaintain.exe
c:\program files\auslogics\boostspeed\taboneclickscanner.exe
c:\program files\auslogics\boostspeed\tabprotect.exe
c:\windows\system32\wintrust.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\sensapi.dll

PID
3144
CMD
"C:\Program Files\Auslogics\BoostSpeed\DiskDefrag.exe" /install
Path
C:\Program Files\Auslogics\BoostSpeed\DiskDefrag.exe
Indicators
No indicators
Parent process
boost-speed-setup.tmp
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
Auslo˜gics
Description
Disk D˜efrag
Version
11.1.0.0
Modules
Image
c:\program files\auslogics\boostspeed\diskdefrag.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\auslogics\boostspeed\axcomponentsvcl.bpl
c:\program files\auslogics\boostspeed\axcomponentsrtl.bpl
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\version.dll
c:\program files\auslogics\boostspeed\rtl250.bpl
c:\windows\system32\mpr.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\opengl32.dll
c:\windows\system32\glu32.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\program files\auslogics\boostspeed\vclimg250.bpl
c:\windows\system32\winmm.dll
c:\program files\auslogics\boostspeed\vcl250.bpl
c:\windows\system32\winspool.drv
c:\windows\system32\comdlg32.dll
c:\windows\system32\oledlg.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\faultrep.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\winsta.dll
c:\windows\system32\uxtheme.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msimg32.dll
c:\program files\auslogics\boostspeed\integrator.exe
c:\program files\auslogics\boostspeed\internetoptimizer.exe
c:\program files\auslogics\boostspeed\tweakmanager.exe
c:\program files\auslogics\boostspeed\taskmanager.exe
c:\program files\auslogics\boostspeed\duplicatefilefinder.exe
c:\program files\auslogics\boostspeed\uninstallmanager.exe
c:\program files\auslogics\boostspeed\startupmanager.exe
c:\program files\auslogics\boostspeed\registrycleaner.exe
c:\program files\auslogics\boostspeed\diskexplorer.exe
c:\program files\auslogics\boostspeed\windowsslimmer.exe
c:\program files\auslogics\boostspeed\deepdiskcleaner.exe
c:\program files\auslogics\boostspeed\tabmaintain.exe
c:\program files\auslogics\boostspeed\taboneclickscanner.exe
c:\program files\auslogics\boostspeed\tabprotect.exe
c:\windows\system32\wintrust.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\psapi.dll

PID
2232
CMD
"C:\Program Files\Auslogics\BoostSpeed\Integrator.exe" /FromInstall
Path
C:\Program Files\Auslogics\BoostSpeed\Integrator.exe
Indicators
No indicators
Parent process
boost-speed-setup.tmp
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
Ausl˜ogics
Description
Boo˜stSpeed
Version
11.1.0.0
Modules
Image
c:\program files\auslogics\boostspeed\integrator.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\program files\auslogics\boostspeed\axcomponentsvcl.bpl
c:\program files\auslogics\boostspeed\axcomponentsrtl.bpl
c:\windows\system32\wininet.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\version.dll
c:\program files\auslogics\boostspeed\rtl250.bpl
c:\windows\system32\mpr.dll
c:\windows\system32\opengl32.dll
c:\windows\system32\glu32.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\program files\auslogics\boostspeed\vclimg250.bpl
c:\program files\auslogics\boostspeed\vcl250.bpl
c:\windows\system32\winspool.drv
c:\windows\system32\comdlg32.dll
c:\windows\system32\oledlg.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\faultrep.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\winsta.dll
c:\windows\system32\uxtheme.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msimg32.dll
c:\program files\auslogics\boostspeed\internetoptimizer.exe
c:\program files\auslogics\boostspeed\tweakmanager.exe
c:\program files\auslogics\boostspeed\taskmanager.exe
c:\program files\auslogics\boostspeed\duplicatefilefinder.exe
c:\program files\auslogics\boostspeed\uninstallmanager.exe
c:\program files\auslogics\boostspeed\startupmanager.exe
c:\program files\auslogics\boostspeed\registrycleaner.exe
c:\program files\auslogics\boostspeed\diskexplorer.exe
c:\program files\auslogics\boostspeed\windowsslimmer.exe
c:\program files\auslogics\boostspeed\deepdiskcleaner.exe
c:\program files\auslogics\boostspeed\tabmaintain.exe
c:\program files\auslogics\boostspeed\taboneclickscanner.exe
c:\program files\auslogics\boostspeed\tabprotect.exe
c:\windows\system32\wintrust.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\psapi.dll

PID
3120
CMD
"C:\Program Files\Auslogics\BoostSpeed\Integrator.exe"
Path
C:\Program Files\Auslogics\BoostSpeed\Integrator.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
Ausl˜ogics
Description
Boo˜stSpeed
Version
11.1.0.0
Modules
Image
c:\program files\auslogics\boostspeed\integrator.exe
c:\systemroot\system32\ntdll.dll

PID
2208
CMD
"C:\Program Files\Auslogics\BoostSpeed\Integrator.exe"
Path
C:\Program Files\Auslogics\BoostSpeed\Integrator.exe
Indicators
Parent process
––
User
admin
Integrity Level
HIGH
Version:
Company
Ausl˜ogics
Description
Boo˜stSpeed
Version
11.1.0.0
Modules
Image
c:\program files\auslogics\boostspeed\integrator.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\program files\auslogics\boostspeed\axcomponentsvcl.bpl
c:\program files\auslogics\boostspeed\axcomponentsrtl.bpl
c:\windows\system32\wininet.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\version.dll
c:\program files\auslogics\boostspeed\rtl250.bpl
c:\windows\system32\mpr.dll
c:\windows\system32\opengl32.dll
c:\windows\system32\glu32.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\program files\auslogics\boostspeed\vclimg250.bpl
c:\program files\auslogics\boostspeed\vcl250.bpl
c:\windows\system32\winspool.drv
c:\windows\system32\comdlg32.dll
c:\windows\system32\oledlg.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\faultrep.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\winsta.dll
c:\windows\system32\uxtheme.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msimg32.dll
c:\program files\auslogics\boostspeed\internetoptimizer.exe
c:\program files\auslogics\boostspeed\tweakmanager.exe
c:\program files\auslogics\boostspeed\taskmanager.exe
c:\program files\auslogics\boostspeed\duplicatefilefinder.exe
c:\program files\auslogics\boostspeed\uninstallmanager.exe
c:\program files\auslogics\boostspeed\startupmanager.exe
c:\program files\auslogics\boostspeed\registrycleaner.exe
c:\program files\auslogics\boostspeed\diskexplorer.exe
c:\program files\auslogics\boostspeed\windowsslimmer.exe
c:\program files\auslogics\boostspeed\deepdiskcleaner.exe
c:\program files\auslogics\boostspeed\tabmaintain.exe
c:\program files\auslogics\boostspeed\taboneclickscanner.exe
c:\program files\auslogics\boostspeed\tabprotect.exe
c:\windows\system32\wintrust.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\psapi.dll

Registry activity

Total events
821
Read events
657
Write events
163
Delete events
1

Modification events

PID
Process
Operation
Key
Name
Value
2436
boost-speed-setup.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Owner
840900002C9318A2DA7ED501
2436
boost-speed-setup.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
SessionHash
4DFB45DD58051BC1CF82FC79E532FB2E80D62179C7C8BE5BFB134FE9337C3E42
2436
boost-speed-setup.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Sequence
1
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auslogics\BoostSpeed\11.x\Settings
General.Tracking.URLMarkers
2436
boost-speed-setup.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2436
boost-speed-setup.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auslogics\BoostSpeed\11.x\Settings
General.Tracking.Param_Source
boost-speed-11
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auslogics\BoostSpeed\11.x\Settings
General.Language
ENU
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auslogics
ClientID
{362103A5-0DC5-4DB5-9898-A438FFA9321D}
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\boost-speed-setup_RASAPI32
EnableFileTracing
0
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\boost-speed-setup_RASAPI32
EnableConsoleTracing
0
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\boost-speed-setup_RASAPI32
FileTracingMask
4294901760
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\boost-speed-setup_RASAPI32
ConsoleTracingMask
4294901760
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\boost-speed-setup_RASAPI32
MaxFileSize
1048576
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\boost-speed-setup_RASAPI32
FileDirectory
%windir%\tracing
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\boost-speed-setup_RASMANCS
EnableFileTracing
0
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\boost-speed-setup_RASMANCS
EnableConsoleTracing
0
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\boost-speed-setup_RASMANCS
FileTracingMask
4294901760
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\boost-speed-setup_RASMANCS
ConsoleTracingMask
4294901760
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\boost-speed-setup_RASMANCS
MaxFileSize
1048576
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\boost-speed-setup_RASMANCS
FileDirectory
%windir%\tracing
2436
boost-speed-setup.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2436
boost-speed-setup.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000092000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2436
boost-speed-setup.tmp
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\801D62D07B449D5C5C035C98EA61FA443C2A58FE
Blob
0F0000000100000014000000F53631B5177626EB6541DF5563C8187D9DCA421A09000000010000005E000000305C06082B0601050507030306082B0601050507030106082B0601050507030206082B0601050507030406082B0601050508020206082B0601050507030606082B0601050507030706082B06010505070308060A2B0601040182370A030453000000010000002400000030223020060A6086480186FA6C0A010230123010060A2B0601040182373C0101030200C014000000010000001400000055E481D11180BED889B908A331F9A1240916B9701D0000000100000010000000E871723E266F38AF5D49CDA2A502669C0B000000010000001000000045006E00740072007500730074000000030000000100000014000000801D62D07B449D5C5C035C98EA61FA443C2A58FE2000000001000000600400003082045C30820344A00302010202043863B966300D06092A864886F70D01010505003081B431143012060355040A130B456E74727573742E6E65743140303E060355040B14377777772E656E74727573742E6E65742F4350535F3230343820696E636F72702E206279207265662E20286C696D697473206C6961622E2931253023060355040B131C286329203139393920456E74727573742E6E6574204C696D69746564313330310603550403132A456E74727573742E6E65742043657274696669636174696F6E20417574686F7269747920283230343829301E170D3939313232343137353035315A170D3139313232343138323035315A3081B431143012060355040A130B456E74727573742E6E65743140303E060355040B14377777772E656E74727573742E6E65742F4350535F3230343820696E636F72702E206279207265662E20286C696D697473206C6961622E2931253023060355040B131C286329203139393920456E74727573742E6E6574204C696D69746564313330310603550403132A456E74727573742E6E65742043657274696669636174696F6E20417574686F726974792028323034382930820122300D06092A864886F70D01010105000382010F003082010A0282010100AD4D4BA91286B2EAA320071516642A2B4BD1BF0B4A4D8EED8076A567B77840C07342C868C0DB532BDD5EB8769835938B1A9D7C133A0E1F5BB71ECFE524141EB181A98D7DB8CC6B4B03F1020CDCABA54024007F7494A19D0829B3880BF587779D55CDE4C37ED76A64AB851486955B9732506F3DC8BA660CE3FCBDB849C176894919FDC0A8BD89A3672FC69FBC711960B82DE92CC99076667B94E2AF78D665535D3CD69CB2CF2903F92FA450B2D448CE0532558AFDB2644C0EE4980775DB7FDFB9085560853029F97B48A46986E3353F1E865D7A7A15BDEF008E1522541700902693BC0E496891BFF847D39D9542C10E4DDF6F26CFC3182162664370D6D5C007E10203010001A3743072301106096086480186F8420101040403020007301F0603551D2304183016801455E481D11180BED889B908A331F9A1240916B970301D0603551D0E0416041455E481D11180BED889B908A331F9A1240916B970301D06092A864886F67D0741000410300E1B0856352E303A342E3003020490300D06092A864886F70D010105050003820101005947AC21848A17C99C89531EBA80851AC63C4E3EB19CB67CC6925D186402E3D3060811617C63E32B9D31037076D2A328A0F4BB9A6373ED6DE52ADBED14A92BC63611D02BEB078BA5DA9E5C199D5612F55429C805EDB2122A8DF4031BFFE7921087B03AB5C39D053712A3C7F415B9D5A439169B533A2391F1A882A26A8868C1790222BCAAA6D6AEDFB0145FB887D0DD7C7F7BFFAF1CCFE6DB07AD5EDB859DD02B0D33DB04D1E64940132B76FB3EE99C890F15CE18B08578214F6B4F0EFA3667CD07F2FF08D0E2DED9BF2AAFB88786213C04CAB794687FCF3CE998D738FFECC0D950F02E4B58AE466FD02EC360DA725572BD4C459E61BABF84819203D1D2697CC5
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\801D62D07B449D5C5C035C98EA61FA443C2A58FE
Blob
19000000010000001000000091FAD483F14848A8A69B18B805CDBB3A030000000100000014000000801D62D07B449D5C5C035C98EA61FA443C2A58FE0B000000010000001000000045006E007400720075007300740000001D0000000100000010000000E871723E266F38AF5D49CDA2A502669C14000000010000001400000055E481D11180BED889B908A331F9A1240916B97053000000010000002400000030223020060A6086480186FA6C0A010230123010060A2B0601040182373C0101030200C009000000010000005E000000305C06082B0601050507030306082B0601050507030106082B0601050507030206082B0601050507030406082B0601050508020206082B0601050507030606082B0601050507030706082B06010505070308060A2B0601040182370A03040F0000000100000014000000F53631B5177626EB6541DF5563C8187D9DCA421A2000000001000000600400003082045C30820344A00302010202043863B966300D06092A864886F70D01010505003081B431143012060355040A130B456E74727573742E6E65743140303E060355040B14377777772E656E74727573742E6E65742F4350535F3230343820696E636F72702E206279207265662E20286C696D697473206C6961622E2931253023060355040B131C286329203139393920456E74727573742E6E6574204C696D69746564313330310603550403132A456E74727573742E6E65742043657274696669636174696F6E20417574686F7269747920283230343829301E170D3939313232343137353035315A170D3139313232343138323035315A3081B431143012060355040A130B456E74727573742E6E65743140303E060355040B14377777772E656E74727573742E6E65742F4350535F3230343820696E636F72702E206279207265662E20286C696D697473206C6961622E2931253023060355040B131C286329203139393920456E74727573742E6E6574204C696D69746564313330310603550403132A456E74727573742E6E65742043657274696669636174696F6E20417574686F726974792028323034382930820122300D06092A864886F70D01010105000382010F003082010A0282010100AD4D4BA91286B2EAA320071516642A2B4BD1BF0B4A4D8EED8076A567B77840C07342C868C0DB532BDD5EB8769835938B1A9D7C133A0E1F5BB71ECFE524141EB181A98D7DB8CC6B4B03F1020CDCABA54024007F7494A19D0829B3880BF587779D55CDE4C37ED76A64AB851486955B9732506F3DC8BA660CE3FCBDB849C176894919FDC0A8BD89A3672FC69FBC711960B82DE92CC99076667B94E2AF78D665535D3CD69CB2CF2903F92FA450B2D448CE0532558AFDB2644C0EE4980775DB7FDFB9085560853029F97B48A46986E3353F1E865D7A7A15BDEF008E1522541700902693BC0E496891BFF847D39D9542C10E4DDF6F26CFC3182162664370D6D5C007E10203010001A3743072301106096086480186F8420101040403020007301F0603551D2304183016801455E481D11180BED889B908A331F9A1240916B970301D0603551D0E0416041455E481D11180BED889B908A331F9A1240916B970301D06092A864886F67D0741000410300E1B0856352E303A342E3003020490300D06092A864886F70D010105050003820101005947AC21848A17C99C89531EBA80851AC63C4E3EB19CB67CC6925D186402E3D3060811617C63E32B9D31037076D2A328A0F4BB9A6373ED6DE52ADBED14A92BC63611D02BEB078BA5DA9E5C199D5612F55429C805EDB2122A8DF4031BFFE7921087B03AB5C39D053712A3C7F415B9D5A439169B533A2391F1A882A26A8868C1790222BCAAA6D6AEDFB0145FB887D0DD7C7F7BFFAF1CCFE6DB07AD5EDB859DD02B0D33DB04D1E64940132B76FB3EE99C890F15CE18B08578214F6B4F0EFA3667CD07F2FF08D0E2DED9BF2AAFB88786213C04CAB794687FCF3CE998D738FFECC0D950F02E4B58AE466FD02EC360DA725572BD4C459E61BABF84819203D1D2697CC5
2436
boost-speed-setup.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFilesHash
C2A182794A937B5B2F8FCD5B7BE55CE79ABA9D4A980872F40CFC759A8E6FA935
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1
Inno Setup: Setup Version
5.5.9 (u)
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1
Inno Setup: App Path
C:\Program Files\Auslogics\BoostSpeed
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1
InstallLocation
C:\Program Files\Auslogics\BoostSpeed\
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1
Inno Setup: Icon Group
Auslogics\BoostSpeed
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1
Inno Setup: User
admin
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1
Inno Setup: Language
enu
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1
DisplayName
Auslogics BoostSpeed 11
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1
DisplayIcon
C:\Program Files\Auslogics\BoostSpeed\Integrator.exe
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1
UninstallString
"C:\Program Files\Auslogics\BoostSpeed\unins000.exe"
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1
QuietUninstallString
"C:\Program Files\Auslogics\BoostSpeed\unins000.exe" /SILENT
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1
DisplayVersion
11.1.0.0
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1
Publisher
Auslogics Labs Pty Ltd
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1
URLInfoAbout
http://www.auslogics.com/en/contact/
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1
HelpLink
http://www.auslogics.com/en/support/
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1
URLUpdateInfo
http://www.auslogics.com/en/checkforupdate/?product=boost-speed&version=11.1.0.0
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1
Readme
http://www.auslogics.com/en/software/boost-speed/
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1
Contact
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1
NoModify
1
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1
NoRepair
1
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1
InstallDate
20191009
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1
MajorVersion
11
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1
MinorVersion
1
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1
VersionMajor
11
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1
VersionMinor
1
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1
EstimatedSize
112276
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1
Inno Setup CodeFile: SplitTestCase
0
2436
boost-speed-setup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Auslogics\BoostSpeed\11.x\Settings
General.InstallDateTime
5BD2DBC37B5CE540
2436
boost-speed-setup.tmp
delete key
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
3360
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FE9301D5-9266-4A2F-8767-85482115CAB0}\1.0
DiskDoctorChecker
3360
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FE9301D5-9266-4A2F-8767-85482115CAB0}\1.0\FLAGS
0
3360
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FE9301D5-9266-4A2F-8767-85482115CAB0}\1.0\0\win32
C:\Program Files\Auslogics\BoostSpeed\DiskDoctorChecker.x32.dll
3360
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FE9301D5-9266-4A2F-8767-85482115CAB0}\1.0\HELPDIR
C:\Program Files\Auslogics\BoostSpeed\
3360
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DCC049B0-CA04-4E58-B4C8-CE62AC6F5096}
IDiskChecker
3360
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DCC049B0-CA04-4E58-B4C8-CE62AC6F5096}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
3360
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DCC049B0-CA04-4E58-B4C8-CE62AC6F5096}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3360
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DCC049B0-CA04-4E58-B4C8-CE62AC6F5096}\TypeLib
{FE9301D5-9266-4A2F-8767-85482115CAB0}
3360
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DCC049B0-CA04-4E58-B4C8-CE62AC6F5096}\TypeLib
Version
1.0
3360
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{278029E0-2347-4254-A65E-204AC55E2508}
Auslogics DiskChecker
3360
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{278029E0-2347-4254-A65E-204AC55E2508}\InprocServer32
C:\PROGRA~1\AUSLOG~1\BOOSTS~1\DISKDO~1.DLL
3360
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{278029E0-2347-4254-A65E-204AC55E2508}\InprocServer32
ThreadingModel
Free
3360
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DiskDoctorChecker.DiskChecker
Auslogics DiskChecker
3360
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DiskDoctorChecker.DiskChecker\Clsid
{278029E0-2347-4254-A65E-204AC55E2508}
3360
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{278029E0-2347-4254-A65E-204AC55E2508}\ProgID
DiskDoctorChecker.DiskChecker
3360
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{278029E0-2347-4254-A65E-204AC55E2508}\Version
1.0
3360
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{278029E0-2347-4254-A65E-204AC55E2508}\TypeLib
{FE9301D5-9266-4A2F-8767-85482115CAB0}
3360
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{278029E0-2347-4254-A65E-204AC55E2508}
AppID
{278029E0-2347-4254-A65E-204AC55E2508}
3360
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{278029E0-2347-4254-A65E-204AC55E2508}
DllSurrogate
2492
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F2C6F7D1-ED32-49E5-9919-00DB857103B2}\1.0
TMAgentCOM
2492
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F2C6F7D1-ED32-49E5-9919-00DB857103B2}\1.0\FLAGS
0
2492
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F2C6F7D1-ED32-49E5-9919-00DB857103B2}\1.0\0\win32
C:\Program Files\Auslogics\BoostSpeed\TaskManagerHelper.Agent.x32.dll
2492
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F2C6F7D1-ED32-49E5-9919-00DB857103B2}\1.0\HELPDIR
C:\Program Files\Auslogics\BoostSpeed\
2492
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6855F0CE-00B1-483F-8633-33B650EE4310}
ITMAgent
2492
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6855F0CE-00B1-483F-8633-33B650EE4310}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
2492
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6855F0CE-00B1-483F-8633-33B650EE4310}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
2492
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6855F0CE-00B1-483F-8633-33B650EE4310}\TypeLib
{F2C6F7D1-ED32-49E5-9919-00DB857103B2}
2492
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6855F0CE-00B1-483F-8633-33B650EE4310}\TypeLib
Version
1.0
2492
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{93469602-4134-4012-A6BC-D46FF1C671E9}
AppID
{93469602-4134-4012-A6BC-D46FF1C671E9}
2492
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{93469602-4134-4012-A6BC-D46FF1C671E9}
DllSurrogate
2492
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{93469602-4134-4012-A6BC-D46FF1C671E9}
Auslogics TMAgent
2492
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{93469602-4134-4012-A6BC-D46FF1C671E9}\InprocServer32
C:\PROGRA~1\AUSLOG~1\BOOSTS~1\TASKMA~1.DLL
2492
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{93469602-4134-4012-A6BC-D46FF1C671E9}\InprocServer32
ThreadingModel
Free
2492
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TMAgentCOM.TMAgent
Auslogics TMAgent
2492
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TMAgentCOM.TMAgent\Clsid
{93469602-4134-4012-A6BC-D46FF1C671E9}
2492
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{93469602-4134-4012-A6BC-D46FF1C671E9}\ProgID
TMAgentCOM.TMAgent
2492
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{93469602-4134-4012-A6BC-D46FF1C671E9}\Version
1.0
2492
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{93469602-4134-4012-A6BC-D46FF1C671E9}\TypeLib
{F2C6F7D1-ED32-49E5-9919-00DB857103B2}
3308
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F2C6F7D1-ED32-49E5-9919-CBF4ABB4456D}\1.0
BrowserPluginsAgentCOM32
3308
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F2C6F7D1-ED32-49E5-9919-CBF4ABB4456D}\1.0\FLAGS
0
3308
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F2C6F7D1-ED32-49E5-9919-CBF4ABB4456D}\1.0\0\win32
C:\Program Files\Auslogics\BoostSpeed\BrowserPluginsHelper.Agent.x32.dll
3308
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F2C6F7D1-ED32-49E5-9919-CBF4ABB4456D}\1.0\HELPDIR
C:\Program Files\Auslogics\BoostSpeed\
3308
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3A3310BE-83DD-4E80-AC51-997CA2BA1080}
IBrowserPluginsAgent32
3308
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3A3310BE-83DD-4E80-AC51-997CA2BA1080}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
3308
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3A3310BE-83DD-4E80-AC51-997CA2BA1080}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3308
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3A3310BE-83DD-4E80-AC51-997CA2BA1080}\TypeLib
{F2C6F7D1-ED32-49E5-9919-CBF4ABB4456D}
3308
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3A3310BE-83DD-4E80-AC51-997CA2BA1080}\TypeLib
Version
1.0
3308
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{93469602-4134-4012-A6BC-F0AD1C3D66AB}
AppID
{93469602-4134-4012-A6BC-F0AD1C3D66AB}
3308
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{93469602-4134-4012-A6BC-F0AD1C3D66AB}
DllSurrogate
3308
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{93469602-4134-4012-A6BC-F0AD1C3D66AB}
Auslogics BrowserPluginsAgent32
3308
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{93469602-4134-4012-A6BC-F0AD1C3D66AB}\InprocServer32
C:\PROGRA~1\AUSLOG~1\BOOSTS~1\BROWSE~2.DLL
3308
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{93469602-4134-4012-A6BC-F0AD1C3D66AB}\InprocServer32
ThreadingModel
Free
3308
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BrowserPluginsAgentCOM32.BrowserPluginsAgent32
Auslogics BrowserPluginsAgent32
3308
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BrowserPluginsAgentCOM32.BrowserPluginsAgent32\Clsid
{93469602-4134-4012-A6BC-F0AD1C3D66AB}
3308
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{93469602-4134-4012-A6BC-F0AD1C3D66AB}\ProgID
BrowserPluginsAgentCOM32.BrowserPluginsAgent32
3308
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{93469602-4134-4012-A6BC-F0AD1C3D66AB}\Version
1.0
3308
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{93469602-4134-4012-A6BC-F0AD1C3D66AB}\TypeLib
{F2C6F7D1-ED32-49E5-9919-CBF4ABB4456D}
3780
Integrator.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
3780
Integrator.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\801D62D07B449D5C5C035C98EA61FA443C2A58FE
Blob
040000000100000010000000BA21EA20D6DDDB8FC1578B40ADA1FCFC0F0000000100000014000000F53631B5177626EB6541DF5563C8187D9DCA421A09000000010000005E000000305C06082B0601050507030306082B0601050507030106082B0601050507030206082B0601050507030406082B0601050508020206082B0601050507030606082B0601050507030706082B06010505070308060A2B0601040182370A030453000000010000002400000030223020060A6086480186FA6C0A010230123010060A2B0601040182373C0101030200C014000000010000001400000055E481D11180BED889B908A331F9A1240916B9701D0000000100000010000000E871723E266F38AF5D49CDA2A502669C0B000000010000001000000045006E00740072007500730074000000030000000100000014000000801D62D07B449D5C5C035C98EA61FA443C2A58FE19000000010000001000000091FAD483F14848A8A69B18B805CDBB3A2000000001000000600400003082045C30820344A00302010202043863B966300D06092A864886F70D01010505003081B431143012060355040A130B456E74727573742E6E65743140303E060355040B14377777772E656E74727573742E6E65742F4350535F3230343820696E636F72702E206279207265662E20286C696D697473206C6961622E2931253023060355040B131C286329203139393920456E74727573742E6E6574204C696D69746564313330310603550403132A456E74727573742E6E65742043657274696669636174696F6E20417574686F7269747920283230343829301E170D3939313232343137353035315A170D3139313232343138323035315A3081B431143012060355040A130B456E74727573742E6E65743140303E060355040B14377777772E656E74727573742E6E65742F4350535F3230343820696E636F72702E206279207265662E20286C696D697473206C6961622E2931253023060355040B131C286329203139393920456E74727573742E6E6574204C696D69746564313330310603550403132A456E74727573742E6E65742043657274696669636174696F6E20417574686F726974792028323034382930820122300D06092A864886F70D01010105000382010F003082010A0282010100AD4D4BA91286B2EAA320071516642A2B4BD1BF0B4A4D8EED8076A567B77840C07342C868C0DB532BDD5EB8769835938B1A9D7C133A0E1F5BB71ECFE524141EB181A98D7DB8CC6B4B03F1020CDCABA54024007F7494A19D0829B3880BF587779D55CDE4C37ED76A64AB851486955B9732506F3DC8BA660CE3FCBDB849C176894919FDC0A8BD89A3672FC69FBC711960B82DE92CC99076667B94E2AF78D665535D3CD69CB2CF2903F92FA450B2D448CE0532558AFDB2644C0EE4980775DB7FDFB9085560853029F97B48A46986E3353F1E865D7A7A15BDEF008E1522541700902693BC0E496891BFF847D39D9542C10E4DDF6F26CFC3182162664370D6D5C007E10203010001A3743072301106096086480186F8420101040403020007301F0603551D2304183016801455E481D11180BED889B908A331F9A1240916B970301D0603551D0E0416041455E481D11180BED889B908A331F9A1240916B970301D06092A864886F67D0741000410300E1B0856352E303A342E3003020490300D06092A864886F70D010105050003820101005947AC21848A17C99C89531EBA80851AC63C4E3EB19CB67CC6925D186402E3D3060811617C63E32B9D31037076D2A328A0F4BB9A6373ED6DE52ADBED14A92BC63611D02BEB078BA5DA9E5C199D5612F55429C805EDB2122A8DF4031BFFE7921087B03AB5C39D053712A3C7F415B9D5A439169B533A2391F1A882A26A8868C1790222BCAAA6D6AEDFB0145FB887D0DD7C7F7BFFAF1CCFE6DB07AD5EDB859DD02B0D33DB04D1E64940132B76FB3EE99C890F15CE18B08578214F6B4F0EFA3667CD07F2FF08D0E2DED9BF2AAFB88786213C04CAB794687FCF3CE998D738FFECC0D950F02E4B58AE466FD02EC360DA725572BD4C459E61BABF84819203D1D2697CC5
3144
DiskDefrag.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
2232
Integrator.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
2208
Integrator.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US

Files activity

Executable files
114
Suspicious files
3
Text files
6
Unknown types
9

Dropped files

PID
Process
Filename
Type
2532
boost-speed-setup.exe
C:\Users\admin\AppData\Local\Temp\is-B17A7.tmp\boost-speed-setup.tmp
executable
MD5: bed87408a645d281b728c8e81efed0bc
SHA256: c837a53377604885d24be6c5c7ebe816f43a783f6e3cce9c8b311125a82916d0
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\CommonForms.Routine.dll
executable
MD5: 5503e88fce3b3065913597775d7ab3c9
SHA256: 996efbc9be274c6a6a2f2d039525baf4e1cced811c312341fd512a35fd6791ed
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\TaskManagerHelper.dll
executable
MD5: 91f3b7614997248fd2d247cb81308d57
SHA256: 00ddf122b71ac32cf77cd35b92679c807f6c1c7b022be55f0694a3b87896623a
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\CommonForms.Site.dll
executable
MD5: 4fbe55fd2c0f4e8276f788da6261a94a
SHA256: e550306deebaff731a59409d5f955e45c6a74bbdbdfd027c48542260002c7f41
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\TaskManager.exe
executable
MD5: 4a204fef60b76cd9e1925ae7137db4e1
SHA256: f806367fb73245659eac6f45fab00de69ab7133f2ba73f4ea2f9f04365a0e36f
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\SystemInformation.exe
executable
MD5: 35248b1aaa286c9959137a2fc6318bbc
SHA256: bf888b54c142ce8f2f901533a188fc222be38f5a061de4afd26f16354cddd5ad
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\TweakManager.exe
executable
MD5: 5f4247574234e967e3f0be6158412537
SHA256: ee20f8e22cd6147153ee74152aaa5afb419ef514de18bebd855b3c1f1756e816
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\SendDebugLog.exe
executable
MD5: 91fb96ab732fd683e445e2cef61c9e22
SHA256: 22179a393b9abdeab90d8ce83ac95e7b7677cfee1ac0ea046fc7529ceaa733c4
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\BrowserPluginsHelper.dll
executable
MD5: c97e81d84386b2fa2290faf35b569273
SHA256: b6f87b2b4a33deae7eb9c0560a4c4849d1a5b4efb7dccd95b2ce0cadf8aae977
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\DebugHelper.dll
executable
MD5: 4b8361edc9cb96f701db3caa731a9ac3
SHA256: 0a6171125f798ad4d78cbdddff058f8102617ca33c103892f78784b3c9cd7112
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\WindowsSlimmerHelper.dll
executable
MD5: 9a3a5c6a09686779e68d6a5c99814639
SHA256: efdc35a2559c687a51a625a7881f232e5ae1edc18fbdfa344ef75231b377b1fc
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\RescueCenterHelper.dll
executable
MD5: ff19d0fc960020ad8b7a2fbf6bc2f36a
SHA256: 49ec4932cdc43a669b9231ad597570e1262d97ec7d6295e5fc90562a33b1dd38
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\Localizer.dll
executable
MD5: 50e8b05d71fa6c4e006ef266d8d5a532
SHA256: f2bf85135fba12fb48b725b21b1112351052395e930422dae41f4bf2e7c4733f
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\SystemInformationHelper.dll
executable
MD5: 6d0e6f10fcd42af5d9f594898235ab38
SHA256: 09b902cdfa279fdf1571de84c14ec3a566bee65e2f4d26ea1de14e7c0eab097e
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\WindowsSlimmer.exe
executable
MD5: 09228240285ad7e1437421b7be6bc31f
SHA256: 06fcf884d9bf799bc80ad5f576e1e14965eba4aae6bc5de13cfea5a9de39b157
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\RescueCenterForm.dll
executable
MD5: 494a194c69085e151864d0a9df4d7a6c
SHA256: e1794c2b7eacbf9a08ae3e444992a597384ab61ff893e26ff73c503640c70ce6
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\CFAHelper.dll
executable
MD5: 5226baaa147346c9f6e82d57326c46d7
SHA256: 7061877bc07a8b131b4476f3b7c11d465bf6665b30a0a50cf5235ee3e4d010fd
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\StartupManager.exe
executable
MD5: 9a214f82ed8e13665a5f463148d2cc29
SHA256: 46938747f676ea0c588cc6653f6a941686feecb92b824d46f1590d8e374b306b
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\BrowserProtectionHelper.dll
executable
MD5: 5dc019b10358c64958a754f8189be10d
SHA256: 7b1978c60b56c3b58e67e257f85591e657133061fbde0d4e8e80180115fa72e4
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\TaskSchedulerHelper.dll
executable
MD5: f143a75f94894a335f2743b8e2a538d1
SHA256: 32124ccfc215b978d8101098090679ff21a268bf6f703e31c444d1f00f747e20
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\sqlite3.dll
executable
MD5: a56d5f74df2302e8ac6488d7d387938f
SHA256: f94c392a275836098cd05c5feb5bf0d676ce7fc30e1f9e59f4bd8c93c08b8b97
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\StartupManagerHelper.dll
executable
MD5: 4233ea98073befd3079c24c4807230c0
SHA256: 492a8344f93ec269210fae01c1432dcc962bcad3c431d2e3ef4f89304429def4
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\BrowserProtection.exe
executable
MD5: a299aee753d3e93210524aa01b6e7cbe
SHA256: 7abbe9a9ae9b1fee1c652d7f44aa05ae1b95adf0b75f8250272e35daa75e5f5a
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\VolumesHelper.dll
executable
MD5: 3480ff03b8492df25d40fc8c399834ae
SHA256: 7a0604f5072ad70569aeffb0edb42f6211a44149458219e4fc9e6e04eea6320d
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\ATToolsExtHelper.dll
executable
MD5: 81e2f665155108764ad3dd1abc64c8b8
SHA256: dc84e3322c3c1afef424e33afa346410dc96a90d8e12b5674ce60cc3f66e74a5
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\InternetOptimizer.exe
executable
MD5: 6a9031532f10cc3fa16442fc663711a4
SHA256: 351c11a36b4dbfae63afe0ff80a0a7081455c16173518512c6a060b32a8a0f65
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\ModeSwitcherHelper.dll
executable
MD5: 11a5da94b0beca02035a74dbcb71b4c5
SHA256: 6201624a4f146650d6091d5c1b5d5ec696377e3679950021f903d5bc5a5b8a0e
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\ShellExtension.dll
executable
MD5: 24e3de438c1df2c110989f9f6edb4d84
SHA256: dca174c5b275aa65f529c124d5f59cf6d47d5d8a81669ec4f090674252baf2c9
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\GoogleAnalyticsHelper.dll
executable
MD5: a0325eaaac30cf4e8a0dcbdb609e79ab
SHA256: 94db60f302080c4a7485dc7ccec8ab208e4e5205c66616f1d5990724a246a102
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\InternetOptimizerHelper.dll
executable
MD5: 9a26bef071af5fed6201d4e9435e979e
SHA256: 6c7ce68d3de9784ef5b47ca6771c56f63305d1372be514b84b8066a83a4231c3
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\ModeSwitcher.exe
executable
MD5: 6e9900e0ab40a48f094a1ae41ca4d652
SHA256: 4ad45454ead08216912c360a944da5ffd4035da1429b9c671333658221c4f465
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\AdvisorHelper.dll
executable
MD5: 9923b9a81b21ddb6a6f9353c22fafda0
SHA256: b08fbdfa3ed8cf4e9404459f6385df9b5d13d53405be0f85d59b3c05d0626e73
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\AxComponentsRTL.bpl
executable
MD5: 0b66a758cfefcf7a6e50a6d58789ba38
SHA256: 4ef572b542f63bdf032ee8696d910e6ffb4171aa8cfb09c01c9036b6ec4e8651
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\FileShredder.exe
executable
MD5: 0c912f9d13a0d7ea6a8948a4843928b7
SHA256: 5f83220ea6c1a0a02576d34b62680d834248d505250e99ccfd5ff7ccfbeb651b
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\DeepDiskCleaner_Settings.dll
executable
MD5: c2cb66cbe573ccb771df813d586eafe8
SHA256: c6a733602e4204cdf82da5cca5e4d8197f2c4668bc39bf4587ab2bf51106f2c8
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\DSSrcAsync.dll
executable
MD5: e84d216a31fc282ab07007c3215efc9b
SHA256: de85c37fb53aee70eeb42b76a9c6367dfee295f64b2f30bdc768a6724402b8ab
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\vclimg250.bpl
executable
MD5: 9e88911c9f265648bec70fe6832751e1
SHA256: 841d186f82e5896dc35237699c7d1a1fd462aed43eb5551eaafc4c53009a3dad
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\FileRecovery.exe
executable
MD5: f6cbce8670da88d12d46fe809c7bb312
SHA256: b8cdc99bafb8e4c0fbc8075649a06b1ad01e2a6e57ae94815bf7855eb0d477cd
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\DeepDiskCleaner.exe
executable
MD5: a5862272373b4e8f1a3055223742ee07
SHA256: 0a6554c80a381a191b8cbaa4ae48cc1673a2b35609288008745fae01dc9cd39e
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\DSSrcWM.dll
executable
MD5: 5d6010f3f5411e7112f3da4fdea0e336
SHA256: 5d11e383568485d51085259190c869e1cfe7bd824727d2d487371c2acf3cd3d9
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\vcl250.bpl
executable
MD5: d1b1912895a377ee99d77157eecb9325
SHA256: 4ea9d7017256e15f54ee9d8a775f7c5348cc903a8cd9939f3fb678f7f58197e7
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\FileShredder_Settings.dll
executable
MD5: d737243d48cc33a8f049e2bf5d107bb1
SHA256: 59209d997870c6f7cf7c1de16e8166162096e0199b3baada3f01742d93c1b012
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\EmptyFolderCleaner.exe
executable
MD5: cea235468b5e28f4d72e575c02619f71
SHA256: ed66d13846ae7b9be17a84d7979af016fb0fd02065ac7ff13b07721e00793a76
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\TrackEraserHelper.dll
executable
MD5: c417ebf0351186ad42137a98b28da591
SHA256: 4864bd0d030327e0a8375e442b7b824343f573f9349ecff4f35c80305fef5084
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\rtl250.bpl
executable
MD5: b8c27c4fa4957106835a29246479ac1d
SHA256: 1aaed1af9965476102c94cdc2c9b0dda62b8b7477b20e0fb9b6da824707ec5db
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\FileRecovery_Settings.dll
executable
MD5: 60caef29b710216b1c390fbe6cc5f4e4
SHA256: 9b436935b50923f43f934bd45b9887fab9dfef1c401d64a45ad507eb13b2f98d
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\TabCareCenter.exe
executable
MD5: 37b5f382995fc8703b391acaad568a9f
SHA256: 384d14a4eda032e3f1fe22330e6a2baf31fc0fa3e5da533846bd010cc6f3ff21
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\BrowserHelper.dll
executable
MD5: 0f450a11387703adfefd0b39da40acee
SHA256: 41b09aa219b913792d88f49070f4517f9b669d5b23b191cf240f9a02ec571e96
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\Setup\SetupCustom.dll
executable
MD5: 5e314ef0df201cf1d87835c4f5c8f162
SHA256: 1e6904ee9b82199b79c146b410610915c7d7c99ee3e1b2dce267b8052114e73f
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\FileRecoveryHelper.dll
executable
MD5: 99cd068857ccac78885ec3f2bba3f262
SHA256: 635b19d284bb7b9a754c2cbc3b1094a9924eaef4a1c35dba35a1494bd47d7fa4
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\TabCleanUp.exe
executable
MD5: 60e05e9468b12469d5d7e36f092d8be4
SHA256: 86c9375fbba5adecba374c6008f3d54fea98f14130363dbe2546b8f861cf24a0
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\ServiceManagerHelper.dll
executable
MD5: 7d0d60c039312f4ea1954f283a8f58fe
SHA256: e9d4ddf8d7c3646a7af4801f70f836ca03ee4223c98b1e3b90e4df4d0f86158d
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\unins000.exe
executable
MD5: bed87408a645d281b728c8e81efed0bc
SHA256: c837a53377604885d24be6c5c7ebe816f43a783f6e3cce9c8b311125a82916d0
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\DuplicateFileFinder.exe
executable
MD5: e3af3c71ad9e9bd83b7ddabf2e667359
SHA256: 58c776c4fae2e3467f818178384c0ca609057fe9fac73f0a2f317f42fca0017b
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\TabDashboard.exe
executable
MD5: 12caa93d6fb158ab5c2d27317e1ccc3c
SHA256: 7b3f84ab904ee3bc3cd93532df08e42ead8d2f458a94e508da10ce12a95ab1f5
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\SpywareCheckerHelper.dll
executable
MD5: 58abcef46b280e5a8ac0b7fad7f584e2
SHA256: 9ab6cb86316e724a8b2b10aac76d79089a81b1cfae9a9f5c7b7b9ba839b48d36
2436
boost-speed-setup.tmp
C:\Users\admin\AppData\Local\Temp\is-GTQSG.tmp\GoogleAnalyticsHelper.dll
executable
MD5: a0325eaaac30cf4e8a0dcbdb609e79ab
SHA256: 94db60f302080c4a7485dc7ccec8ab208e4e5205c66616f1d5990724a246a102
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\DuplicateFileFinder_Settings.dll
executable
MD5: 99c80af26483191d09a6c3134f3d4193
SHA256: c7125a192ed8e6f2f35fb44f9c8d42db5f23f4c2a35a58c51b04e5ba3bcabfa8
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\TabMaintain.exe
executable
MD5: e4befab9ff219bd4bd864dd10f01f2eb
SHA256: 0f4bf120629dc7ff6599f07c6d9a1238acca227d993fc53ee2d796a20e77acc3
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\DiskCleanerHelper.dll
executable
MD5: e8ccf42b43ceb4dc3fcd16a18594c1a1
SHA256: 38f93e97fe565a09fd4aa28f6379b8619c5e72c29fe748989015471e02994c75
2436
boost-speed-setup.tmp
C:\Users\admin\AppData\Local\Temp\is-GTQSG.tmp\vclimg250.bpl
executable
MD5: 9e88911c9f265648bec70fe6832751e1
SHA256: 841d186f82e5896dc35237699c7d1a1fd462aed43eb5551eaafc4c53009a3dad
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\DuplicateFileFinderHelper.dll
executable
MD5: ef144c3c04b8cdbaba218e96fc721059
SHA256: 9ef8242bd8a37ee15a3231ee41c1a78d32c7417a85167b022cae0d8d3a265c82
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\TabMaintain_Settings.dll
executable
MD5: 4f5a7434a41da6049c18e0ef38c5d246
SHA256: ab1d8f90f09bee13ac3bad67288788dfd53e5df45fd046ce42cb226aa27be5d1
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\accessibility_sdk.dll
executable
MD5: 3769bc38db54ae4930d04970ac66edf0
SHA256: 52925fb9db09e7c521f8d65d9681a2147a460e1b218befa8bd1cd86e187689d1
2436
boost-speed-setup.tmp
C:\Users\admin\AppData\Local\Temp\is-GTQSG.tmp\vcl250.bpl
executable
MD5: d1b1912895a377ee99d77157eecb9325
SHA256: 4ea9d7017256e15f54ee9d8a775f7c5348cc903a8cd9939f3fb678f7f58197e7
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\FreeSpaceWiper.exe
executable
MD5: 12f8edbb06361b5b52379505f3c066c3
SHA256: 784c9d5907b03469457ad63464b2bc851e99c0f370a4f430ab48604409a191d1
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\TabOneClickScanner.exe
executable
MD5: 7616dca0adf2d66c5815ea0e653a4267
SHA256: 7c19120c83d3b12222b8a0d3659d2fe4b25d1d15e6d0fb3dd551643fa17057af
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\ShellExtension.ContextMenu.x32.dll
executable
MD5: cefbfc357c15473e01af9886303abb7c
SHA256: 9d9dff5848e482054bd76e93790b60a5cfb7d77b0f7c2cb533f389630caec4e3
2436
boost-speed-setup.tmp
C:\Users\admin\AppData\Local\Temp\is-GTQSG.tmp\rtl250.bpl
executable
MD5: b8c27c4fa4957106835a29246479ac1d
SHA256: 1aaed1af9965476102c94cdc2c9b0dda62b8b7477b20e0fb9b6da824707ec5db
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\FreeSpaceWiper_Settings.dll
executable
MD5: 670f734f6792e8854e98aa93bb964739
SHA256: e9e8edc78d0439f0381a52f3cedf16bfc450b32f8cc51b6f8433342f8b22f89a
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\TabOneClickScanner_Scheduler.dll
executable
MD5: 98919c46028db71096fb4a50781cf04b
SHA256: edd7523583fec6ad3958f821a32cccc5bb1cb720289c90827266fce9f7df8cb1
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\DiskDoctorChecker.x32.dll
executable
MD5: ac6e31a08151775c3de0c5c5f45d9be3
SHA256: 95ceef773b74f789bd4af7ad558d11cb7d179ffa392b9fedfe2abfa88a2005ec
2436
boost-speed-setup.tmp
C:\Users\admin\AppData\Local\Temp\is-GTQSG.tmp\AxComponentsRTL.bpl
executable
MD5: 0b66a758cfefcf7a6e50a6d58789ba38
SHA256: 4ef572b542f63bdf032ee8696d910e6ffb4171aa8cfb09c01c9036b6ec4e8651
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\DiskWipeHelper.dll
executable
MD5: 939d19fd443dcea4e92af11d82e5c773
SHA256: b0b5f677b363ffa1272a4792c96b8eaeecbb870d6e7ff45b26656dda36545a0f
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\TabOptimize.exe
executable
MD5: 5d6b06b69d2e9924d1b8d3573605df5b
SHA256: 9e59549e947541a86b8a84cc90c85bcfe4af7e0f6c01229cbc1a857c8d252483
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\TaskManagerHelper.Agent.x32.dll
executable
MD5: e770c23dcd6c6c0dccd904cc54184e02
SHA256: c3083bc3da123c9e60a8a2b4cd79f7e3f12c83009cc25f642b90134ab73111d0
2436
boost-speed-setup.tmp
C:\Users\admin\AppData\Local\Temp\is-GTQSG.tmp\Localizer.dll
executable
MD5: 50e8b05d71fa6c4e006ef266d8d5a532
SHA256: f2bf85135fba12fb48b725b21b1112351052395e930422dae41f4bf2e7c4733f
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\DiskExplorer.exe
executable
MD5: 8a1a7dfc24d997d36f09c07ab6a18e6d
SHA256: 3be85f38fcf90991582a92fa7720aad6e99fa88cf55f73df0524cfef06cbdc27
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\TabProtect.exe
executable
MD5: 02d58a3c168e6104c0e8af633f149965
SHA256: 34db5c65d39ccacf0b4d12ea3d04a4849671399e6d62790b7948dc913f5c4e00
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\BrowserPluginsHelper.Agent.x32.dll
executable
MD5: e9e960b2c91b5ea7a630cf2439038784
SHA256: e18d4fb9701f9dc6b4dfd123e18fe62a3eef36fe282f853cfc18cd8a65022bcc
2436
boost-speed-setup.tmp
C:\Users\admin\AppData\Local\Temp\is-GTQSG.tmp\CommonForms.Site.dll
executable
MD5: 4fbe55fd2c0f4e8276f788da6261a94a
SHA256: e550306deebaff731a59409d5f955e45c6a74bbdbdfd027c48542260002c7f41
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\DiskExplorerHelper.dll
executable
MD5: e2d08e4b58f730605de0fe35bd975eb9
SHA256: 5f833f5915c306c4d99fd4ece484342d5c45ba6fa2d49387fcfd0a3438002029
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\TabProtect_Scheduler.dll
executable
MD5: 7fda264818538adc06f25569c1367787
SHA256: 904640518115d5028062d84b23917a366dc522d253de0707ca3909391de83d28
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\rdboot32.exe
executable
MD5: 5d87f1070bf08081dd9af4682013502a
SHA256: 1af0bc90615994bffaa61fc69488a2c4be270281b04cd8b42da44e0ba59dfb4a
2436
boost-speed-setup.tmp
C:\Users\admin\AppData\Local\Temp\is-GTQSG.tmp\sqlite3.dll
executable
MD5: a56d5f74df2302e8ac6488d7d387938f
SHA256: f94c392a275836098cd05c5feb5bf0d676ce7fc30e1f9e59f4bd8c93c08b8b97
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\DiskDoctor.exe
executable
MD5: 6031c7fe4619d9a88f90b5eb2d5705dc
SHA256: 272d56dbde787cb1b4e7d8f5edb071d5ac5af786165266d83da1705d949599ea
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\TabReports.exe
executable
MD5: eb06c6883847cf59efac5b8fb11df421
SHA256: 50467603bc999c45a3b2b55a75e97d012b32b1e4ccf8168a75117ea987caa643
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\StartupManagerDelayStart.x32.exe
executable
MD5: 9a1c7157b62b948355759de8827810b2
SHA256: 4d4f6148cab3b5ba6d75ff1ee4dc2c2d21e5c767be4e6b6d2e7918e522bbd4dd
2436
boost-speed-setup.tmp
C:\Users\admin\AppData\Local\Temp\is-GTQSG.tmp\BrowserHelper.dll
executable
MD5: 0f450a11387703adfefd0b39da40acee
SHA256: 41b09aa219b913792d88f49070f4517f9b669d5b23b191cf240f9a02ec571e96
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\DiskDoctorHelper.dll
executable
MD5: 6bdc885cb03865768c2bf5e43e7d5241
SHA256: c0a51a37b7490f34ecf00728ab90ec57c49342d2ef797817202ca46ba7acd544
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\TabAllTools.exe
executable
MD5: 450b7a2595a10f2fc271d584573e4c94
SHA256: af3a9daa99d8ccd93c39f55fb1aa36ff84c28c2f9f0a5f9c3542a33202a5e41e
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\ActionCenterHelper.dll
executable
MD5: 2f8aad893b9abe1cbec5e60a2585ad50
SHA256: 299c14d7a870ad6cd0fd92e43dbaa11a70eac044ee17d054fedc58ad5ef09a4c
2436
boost-speed-setup.tmp
C:\Users\admin\AppData\Local\Temp\is-GTQSG.tmp\CFAHelper.dll
executable
MD5: 5226baaa147346c9f6e82d57326c46d7
SHA256: 7061877bc07a8b131b4476f3b7c11d465bf6665b30a0a50cf5235ee3e4d010fd
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\cdefrag.exe
executable
MD5: 32e086dfb9b50b7399136b3c1f1f1342
SHA256: 1127838f43ec0c3fc80f912c74c8e865f9c07744e54c8dc3c649cb06338b2a3e
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\TabWin10Protector.exe
executable
MD5: b6fa924bebea8ff2e909145fee8a1277
SHA256: a08b9b74113ae0f0e5a19ade75c9f0e9cd1554cc0c947e95078b8e0594ccfbed
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\ActionCenter.exe
executable
MD5: cc12df095e858778c951c1f047656bc6
SHA256: e04e051cf3229c506b12561ef9616c82e4347830dded9d4d911d55643a097500
2436
boost-speed-setup.tmp
C:\Users\admin\AppData\Local\Temp\is-GTQSG.tmp\SetupCustom.dll
executable
MD5: 5e314ef0df201cf1d87835c4f5c8f162
SHA256: 1e6904ee9b82199b79c146b410610915c7d7c99ee3e1b2dce267b8052114e73f
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\UninstallManagerHelper.dll
executable
MD5: 2340adb6fc3b4fac8b0f11fd0c7ad079
SHA256: a129fc9c50156d233d3f20d33772262dff2fb22c0e94a75c73a3f2fea45454f7
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\Integrator.exe
executable
MD5: 1b70dcd0e14e1ff2ed687e3098fcfbd9
SHA256: 614580b61ed22996eac0612e9e92ef221f89fae4e8512d073221e615f2547fa0
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\UninstallManager.exe
executable
MD5: 02228ecae1c8a436452a490df37ebcd3
SHA256: c4df164b0d61befe8162dfe581c1049cefb7babb8f5a8fe8994911ec7e076616
2436
boost-speed-setup.tmp
C:\Users\admin\AppData\Local\Temp\is-GTQSG.tmp\Integrator.exe
executable
MD5: 1b70dcd0e14e1ff2ed687e3098fcfbd9
SHA256: 614580b61ed22996eac0612e9e92ef221f89fae4e8512d073221e615f2547fa0
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\RegistryDefragHelper.dll
executable
MD5: 5a6d580ad836e78d1212d0b8e012d2f4
SHA256: e2099061334b902bebfeaba0322922ccbdccdcde7e0a0ca0215804256c6b0dfd
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\BoostSpeed.exe
executable
MD5: 2dff3475be1f6aec11452e570fbbadcb
SHA256: 8bbe6f36bbe4372f39648120b5a3108f8b51d77099cc6f9dcfc0cc441cda3023
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\RegistryDefrag.exe
executable
MD5: e1280f9a9d79d5253c18265e9a14810a
SHA256: c5a900559438576997252e29a4625d252d7feef1f2096760af53dc46389f06d0
2436
boost-speed-setup.tmp
C:\Users\admin\AppData\Local\Temp\is-GTQSG.tmp\reader.exe
executable
MD5: 458d626c371b0c9a3df77340fec128dc
SHA256: 731d5634c4e31f124e40e8f4d65636a0351d386729571624838fa91d9c061ff1
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\DiskDefrag.exe
executable
MD5: 903ad2fa93b6e62c76b7847aea537a0d
SHA256: c33d6efe4bd750c7abad4e9244384657f87e77c56cd96392a9d3e9070816d584
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\Main.exe
executable
MD5: b0ca0ef63e394c90a17d9155fd85d007
SHA256: aab2cf5e70a920d5679a03448de7a9c0360af9fb8b5aabec46a0ae0be4bcfcae
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\RegistryCleaner.exe
executable
MD5: 1e767bd4e66818232d678eddb2f33be8
SHA256: aeefca6f0699a400315058d85e4f115393b6f1f04858f6ebad37f0fa2aa9398c
3824
boost-speed-setup.exe
C:\Users\admin\AppData\Local\Temp\is-V355O.tmp\boost-speed-setup.tmp
executable
MD5: bed87408a645d281b728c8e81efed0bc
SHA256: c837a53377604885d24be6c5c7ebe816f43a783f6e3cce9c8b311125a82916d0
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\DiskDefragHelper.dll
executable
MD5: e2a8140436f555ad89e3366485527408
SHA256: db93a59bbaaab8000ce4aaff0989bd62862311687052ad85a80337953069824f
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\RegistryCleanerHelper.dll
executable
MD5: ae1e32413183fb92c812f980fd0bd2a4
SHA256: df0b93a2efd5b55d2cfad78ee22d4edfb40cee06a0df06a033dc4035ac92c080
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\DiskDefrag_Settings.dll
executable
MD5: b7f66232840247b3e8486331d91c8add
SHA256: e18bf2bec73d5ecb6975539aea8c0112e35e0e5a6862b0a7003e5157cf23efa3
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\DiskDefrag_Scheduler.dll
executable
MD5: 6281ab996ffc9fc59ab9576d6ffafb05
SHA256: a0f257dde5f6dd61dab675bcbe47d95888631092d53cfcc7d09ce5db865a6bf9
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\ReportHelper.dll
executable
MD5: f5e761826cfcca92e1ebc1a0857854bb
SHA256: 148dbaf037510d3bc62c82f5e5e158f8fed919154d8efc83346c33877bf8e2b8
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\Data\Applications.dat
abr
MD5: f0581d75de775870d5a2e7797aa33672
SHA256: 4e79163db5c6ab946187ba21bcd970870c6504ebdad976d1b93d2c1fd065b359
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-EC5RT.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-PFQ0P.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-3EJCL.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-1N7L2.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-6QSQ1.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-UF3CF.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-4L8LP.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-PAHQ6.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-KIVTP.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-15U7R.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-8NP2D.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-QOA0P.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-7EAR0.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-AN89C.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-PM53C.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\Data\is-75BA6.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-2V31S.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-8POVU.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-2Q78K.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-R4GLI.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-33B8R.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-LMAFA.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-PEB3H.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\TweakManagerHelper.dll
odttf
MD5: f6ed4838df0c8772f9e094f1a5055e65
SHA256: 16c6f1879a07445a6308ba32d1f3206a35b2814afd1ee25442df6fb611f4c8e4
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-QAR6H.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-NL3LQ.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-RQUOI.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\unins000.dat
dat
MD5: e018fed64b2b6381b4fa5a366f0e9599
SHA256: dfbcd6cf9811b47dca7e81502e87f77aed3dfafa890bf0840847cacbc072f5e5
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-IKFRQ.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-NAQQC.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-7C31H.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-0ODPI.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-DA8DT.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-HUKLH.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-4CTVE.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics\BoostSpeed\Uninstall Auslogics BoostSpeed 11.lnk
lnk
MD5: 0717751393064cc17a3df8364c24142c
SHA256: de6c84a370309a0035746a278f6cb66981d8a92f97a60c49295aa7a386f45c5e
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-AB3G6.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-N9ED1.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-RSJSJ.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-N9IEQ.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-N3GUB.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-OCECC.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-2SAUH.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-LKCU8.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-9EC67.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-ARE9S.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-RRT80.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-2LLCU.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-FOJ20.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-8J8QR.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-8MTB2.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-V7EQ4.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-4BD24.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-4IVTS.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-29HB0.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-QS1J0.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-AHN77.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-B3PMO.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-G18EA.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Users\admin\Desktop\Auslogics BoostSpeed 11.lnk
lnk
MD5: d7421af4a3e01a169b2cc481eaa7c1bf
SHA256: db5850a9032222763f532fdb36c37c43b45abc68bc55d7196da859fe2a706a32
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-A68C6.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-7BPQ5.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-2IF0Q.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-3LB4S.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-IP206.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-O58OU.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-C955G.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-4JUT3.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-E41GK.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-MNOU4.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-HVROM.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-12AAG.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-3N635.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics\BoostSpeed\Auslogics BoostSpeed 11 on the Web.url
text
MD5: 2cd0689c1a59396c4ae06d9f6cb6af85
SHA256: 376ff60d00b93e1cba8aa6d040ae8c4649005e0a2fa6a20f2e7644252a8f9776
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-27FK6.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-4TUVM.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-04S1T.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-I8AHE.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-EQTLT.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-ER2SL.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-00MAD.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\ATToolsStdHelper.dll
odttf
MD5: 53a9bef413f76459bca8fbc591aa9704
SHA256: 4f11f780df9369a035efdfe64d91385ac946d38f3bf4a15a1aa2df45d38e2f08
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-JFF8O.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-S7NTI.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-FDCDL.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\AxComponentsVCL.bpl
odttf
MD5: efe523f088aed0931155177137b8e9a7
SHA256: 1017958f1abd61a9ed019b1db12eaaa09158f9692c4f10875de622685f2b524f
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-3LLFM.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-PB8GU.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-L4NK5.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-9TUE1.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-BI4J9.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-OACDU.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-I0SIP.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics\BoostSpeed\Auslogics BoostSpeed 11.lnk
lnk
MD5: 895de706fc224a90e9095b441e551a8a
SHA256: f52cc58ddbed821cacc043c9dbf16f0a5e76aadaaba2febcdb8c6886251da3ff
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-D8OHA.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\Data\main.ini
text
MD5: a3eb18c6c6504a0bf3c01563963ea74a
SHA256: e0ff5c0b4d916816b37f65cbb8c81b3e73dc6c8ad2c9372ff53403b37eb78c55
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\Data\is-VCJ2M.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-B02NV.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\Setup\is-GAFEQ.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\Lang\enu.lng
binary
MD5: 66728a8c5ac7b51705a373441413f2b6
SHA256: f4de14288d43451cef3d358f82b5c28712c43b7dba81bedb4cf827c537422a13
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\Lang\is-2ABB9.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\EULA.rtf
text
MD5: db5f6ce168c46b096782bba840aa8c85
SHA256: 5a73e46d1c33f259ebfaa0c6a195b87b4ca15009a6e1fa622e6d899a26dd41ff
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-HMAQ1.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-Q8LQ0.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-AS7S7.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\ProgramData\Auslogics\BoostSpeed\11.x\$$$Cookies161367510
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\ProgramData\Auslogics\BoostSpeed\11.x\$$$Databases.db161367510
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\ProgramData\Auslogics\BoostSpeed\11.x\$$$Databases.db161367494
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\ProgramData\Auslogics\BoostSpeed\11.x\$$$Cookies161367494
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\ProgramData\Auslogics\BoostSpeed\11.x\$$$Databases.db161367463
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\ProgramData\Auslogics\BoostSpeed\11.x\$$$Cookies161367463
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-HSVIR.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Users\admin\AppData\Local\Temp\is-GTQSG.tmp\enu.lng
binary
MD5: 66728a8c5ac7b51705a373441413f2b6
SHA256: f4de14288d43451cef3d358f82b5c28712c43b7dba81bedb4cf827c537422a13
2436
boost-speed-setup.tmp
C:\Users\admin\AppData\Local\Temp\is-GTQSG.tmp\main.ini
text
MD5: a3eb18c6c6504a0bf3c01563963ea74a
SHA256: e0ff5c0b4d916816b37f65cbb8c81b3e73dc6c8ad2c9372ff53403b37eb78c55
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-G0MHF.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Users\admin\AppData\Local\Temp\is-GTQSG.tmp\EULA.rtf
text
MD5: db5f6ce168c46b096782bba840aa8c85
SHA256: 5a73e46d1c33f259ebfaa0c6a195b87b4ca15009a6e1fa622e6d899a26dd41ff
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-KT37D.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-VD2HQ.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Users\admin\AppData\Local\Temp\is-GTQSG.tmp\AxComponentsVCL.bpl
odttf
MD5: efe523f088aed0931155177137b8e9a7
SHA256: 1017958f1abd61a9ed019b1db12eaaa09158f9692c4f10875de622685f2b524f
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-R5FG9.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-RV89A.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\setup uninstall.ico
image
MD5: fc1ac7453918b607f349dbbc776b940d
SHA256: 94ae9d061102e1e8d3bc570115bf8836f42ddf1e04beed6cc65756ff390c033c
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-3IB22.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-78NB7.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-B9922.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-G1U7O.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-MN6HN.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-PN3OL.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\is-81I3G.tmp
––
MD5:  ––
SHA256:  ––
2436
boost-speed-setup.tmp
C:\Program Files\Auslogics\BoostSpeed\unins000.msg
binary
MD5: 79173da528082489a43f39cf200a7647
SHA256: 4f36e6be09cd12e825c2a12ab33544744e7256c9094d7149258ea926705e8ffd

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
5
TCP/UDP connections
2
DNS requests
2
Threats
1

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
2436 boost-speed-setup.tmp POST 200 172.217.23.174:80 http://www.google-analytics.com/collect US
text
image
whitelisted
2436 boost-speed-setup.tmp POST 200 172.217.23.174:80 http://www.google-analytics.com/collect US
text
image
whitelisted
2436 boost-speed-setup.tmp POST 200 172.217.23.174:80 http://www.google-analytics.com/collect US
text
image
whitelisted
2436 boost-speed-setup.tmp POST 200 172.217.23.174:80 http://www.google-analytics.com/collect US
text
image
whitelisted
2436 boost-speed-setup.tmp POST 200 172.217.23.174:80 http://www.google-analytics.com/collect US
text
image
whitelisted

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
2436 boost-speed-setup.tmp 45.33.8.241:443 Linode, LLC US malicious
2436 boost-speed-setup.tmp 172.217.23.174:80 Google Inc. US whitelisted

DNS requests

Domain IP Reputation
www.auslogics.com 45.33.8.241
malicious
www.google-analytics.com 172.217.23.174
whitelisted

Threats

No threats detected.

Debug output strings

No debug info.